Skip to main content
SSD and hard drive connected to a workstation through a write blockerAI-generated

Service

Windows forensics

Windows records activity in many parallel places. Registry hives, event logs, NTFS metadata and execution artefacts together allow a timeline to be reconstructed even when individual traces have been removed.

What is examined

  • NTFS metadata, journal entries and deleted file remnants
  • Registry hives, user profiles and autostart entries
  • Event logs, logon events and remote access
  • Execution traces, USB history and connected storage media

How the examination is carried out

  1. 1.Acquisition through a write blocker, with verified hashes
  2. 2.Parsing of the artefact groups with independent tools
  3. 3.Cross-checking of contradictory timestamps
  4. 4.Documentation of findings, methods and remaining uncertainty

Technical limits

These limits are stated before the instruction, not afterwards.

  • Event logs rotate and may no longer cover the period in question.
  • Anti-forensic clean-up tools can remove artefacts irreversibly.
  • Encrypted volumes without keys remain inaccessible.
  • Timestamps can be manipulated; this is stated where it is detected.

FREQUENTLY ASKED QUESTIONS

Windows forensics: frequently asked questions

Equipment used

Systems used in this examination

Next step

Discuss your case

Describe the situation briefly. We will say what can realistically be established, and what cannot.

+49 221 99981 490ContactBook an appointment